Selective Network Traffic Mirroring via Bitwise Granular Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems, including firewalls and anti-virus software, have limited monitoring and reaction capabilities, failing to detect new types of attacks and prevent their propagation within local area networks, and are inefficient due to non-deterministic performance and high costs associated with advanced hardware components.
Innovation Solution
An apparatus that facilitates selective mirroring of network traffic through processing based on provisioned rules and policies, using a data processor to generate mirrored data with bitwise granularity across headers and payloads, enabling flexible and advanced network security and monitoring features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If advanced security systems use off-the-shelf computer system components (CPUs, memory, operating systems), then the device complexity is reduced and cost is lowered, but the monitoring and detection capabilities are insufficient and performance is non-deterministic
Solution Approach 1:
The patent segments the network security system into multiple specialized functional modules: a network processor for high-speed packet processing, content addressable memory for signature matching, and a rule engine for policy-based traffic management. This segmentation allows each component to be optimized for its specific function, achieving deterministic performance while maintaining reasonable complexity.
Solution Approach 2:
The patent introduces a specialized network processor as an intermediary between the standard CPU and the network traffic. This intermediary handles the computationally intensive tasks of packet inspection, signature matching, and traffic filtering, freeing the standard CPU from real-time processing demands and enabling deterministic security operations.
2Ease of manufacture
If hardware architectures are not customized for network security applications, then the ease of manufacture is improved and cost is reduced, but the performance is non-deterministic and validation is difficult
Solution Approach 1:
The patent designs a network security apparatus that combines multiple functions into a single platform: intrusion detection, traffic filtering, packet inspection, and logging. By making the system universal and multi-functional, it achieves high processing speeds for various security tasks without requiring separate specialized hardware for each function, thus maintaining manufacturing efficiency.
Solution Approach 2:
The patent employs content addressable memory (CAM) with configurable parameters for signature matching and pattern recognition. By allowing dynamic configuration of search parameters and matching criteria, the system achieves high-speed processing adaptable to different security requirements while using standard hardware components that are easy to manufacture.
3Productivity
If memory hierarchy, caches, or complex queuing structures are added to support high bandwidth and low latency, then the productivity is improved, but the device complexity increases
Solution Approach 1:
The patent extracts the complex memory hierarchy and caching functions into dedicated network processor components that are optimized for packet processing. Rather than adding complex memory structures to a general-purpose system, the extraction principle is applied by using specialized hardware blocks within the network processor that handle high-speed packet buffering and caching, thus achieving high bandwidth without significantly increasing overall system complexity.
4Ease of operation
If firewall filters traffic based on packet header only, then the ease of operation is improved and processing speed is maintained, but the detection capability for deep packet contents is lost
Solution Approach 1:
The patent implements a dynamic traffic inspection system that adapts its inspection depth based on traffic characteristics and security policies. The rule engine dynamically determines whether to perform shallow header-only filtering or deep packet inspection based on configured policies, threat levels, and resource availability. This dynamic approach maintains operational simplicity while enhancing detection capability when needed.
Solution Approach 2:
The patent applies different inspection depths to different traffic flows based on local quality requirements. Critical traffic types (e.g., known malicious patterns, high-risk ports) receive deep packet inspection with full payload analysis, while normal traffic receives faster header-only filtering. This local differentiation maintains overall system simplicity while providing enhanced detection where necessary.
Data Source
AI summary
An apparatus is described that facilitates selective mirroring through processing of network traffic in accordance with provisioned rules and policies. The apparatus includes a port included in a set of at least one port, wherein each port in the set receives input traffic, a data processor that processes input data from the set of at least one port to generate mirrored data, based on rules with bitwise granularity across a header and a payload of the input data, and a mirror port selectable from the set of at least one port that transmits output traffic corresponding to the mirrored data. Advantageously, the apparatus provides an architectural framework well suited to a low cost, high speed, robust implementation of selective mirroring that enables flexible, advanced network security and monitoring features and network traffic analysis.


